Hacker News new | ask | show | jobs
by ChrisSD 2901 days ago
You'll also want the CSP `sandbox` policy on the `src` page to guard against direct linking.

[0] https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Co...